A recently disclosed vulnerability, tracked as CVE-2026-1731, affects BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA). The flaw is rated critical, with a CVSS v4 score of 9.9 according to the National Vulnerability Database. BeyondTrust published advisory BT26-02 confirming that an unauthenticated remote attacker may be able to execute operating system commands by sending specially crafted client requests. This article provides an analysis of the issue, its technical and business impact, and publicly documented remediation guidance.
BeyondTrust Privileged Remote Access (CVE-2026-1731)
The vulnerability arises from improper validation of client-supplied data within the request handling components of BeyondTrust RS and older PRA instances. According to the vendor advisory, the issue can be triggered pre-authentication, which makes it particularly severe. An attacker can send specially crafted requests to the affected service endpoint. This causes the target system to process malicious input in a way that leads to arbitrary operating system command execution under the context of the site user.
To successfully exploit the flaw, an attacker requires only network access to the affected server and does not need valid credentials. This makes external attack surface exposure a significant concern for organisations that publish RS or PRA systems to the internet.
Impact of CVE-2026-1731
At a technical level, exploitation grants the attacker the ability to run operating system commands with the permissions of the site user account. This can allow lateral movement, deployment of backdoors, and extraction of sensitive information depending on the configuration of the host and its network connectivity.
From a business perspective, this type of compromise can result in service outages, data disclosure incidents, and potential regulatory concerns where personal or sensitive data is involved. Remote access platforms often sit in privileged positions within enterprise environments, which further elevates the associated risk. The exposure of more than 11,000 systems, as referenced in open reporting, highlights the operational scale of the issue for organisations that rely on these products.
Mitigation of the BeyondTrust Remote Support vulnerability
BeyondTrust has released security patches and updated versions to address CVE-2026-1731. Public sources, including vendor guidance, confirm the following fixed versions:
- Remote Support: Patch BT26-02-RS or version 25.3.2 and later.
- Privileged Remote Access: Patch BT26-02-PRA or version 25.1.1 and later.
Organisations using self-hosted deployments should apply the relevant patch immediately or upgrade to a secure release. BeyondTrust also recommends enabling automatic updates where possible.
Exposure of internet-facing instances should be reviewed, and network segmentation applied to reduce the accessible attack surface. A patch has been applied to all Remote Support SaaS and Privileged Remote Access SaaS customers as of the 2nd of February 2026 that remediates this vulnerability.
How Can Sentrium Help?
Sentrium supports organisations in assessing their exposure to vulnerabilities in remote access platforms. Our penetration testing services help identify weaknesses before they can be exploited. We assist teams in evaluating patch management processes and improving the resilience of remote access infrastructure. If you would like to discuss how we can support your security programme, get in touch with our team or get an instant quote.